Incorrect Conversion between Numeric Types in Linux kernel - CVE-2026-98049
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to produce incorrect 32-bit compare-and-exchange results.
The vulnerability exists due to incorrect numeric conversion in the BPF cmpxchg instruction detection logic when executing a BPF program that performs a 32-bit compare-and-exchange on an arena pointer. A local user can execute a BPF program containing the affected operation to produce incorrect 32-bit compare-and-exchange results.
The issue is relevant on architectures where 32-bit compare-and-exchange operations require explicit zero extension of the destination register.